Let's say I own a domain like "worldsbestwebsite.com" and I am running my Sugar install on something like "sugar.worldsbestwebsite.com".

Are there tools that would allow someone (hacker) to find the subdomain (or all sub domains) from a given domain name?

Just being paranoid here . . .